Information Security Engineer (Mumbai)

Information Security Engineer (Mumbai)

22 Aug
|
Kotak Mahindra Bank
|
Mumbai

22 Aug

Kotak Mahindra Bank

Mumbai

IT Governance, Risk Management & User Access Review

IT Infrastructure, Cybersecurity & Cloud Operations

JOB TITLE - IT Governance, Risk Management & User Access ReviewDEPARTMENTIT Infrastructure, Cybersecurity & Cloud OperationsREPORTING TOLead - IT Infra Governance, Risk & Compliance

Job Purpose To lead Governance, Risk Management and User Access Governance activities across IT Infrastructure, Cybersecurity and Cloud Operations. The role is responsible for establishing governance frameworks, conducting risk and control assessments, overseeing User Access Management (UAM) and User Access Reviews (UAR), monitoring key technology initiatives, and providing management reporting to ensure operational resilience, regulatory adherence and effective control governance.

Key Responsibilities

1. Governance Framework & Policy Management

- Define, implement and maintain governance frameworks for IT Infrastructure, Cybersecurity and Cloud Operations.
- Establish and maintain process documentation, SOPs, standards, operating procedures and governance controls.
- Develop and monitor Key Risk Indicators (KRIs) and governance metrics.
- Evaluate adherence to approved policies, standards and operating procedures.
- Maintain a central repository of governance artefacts, approvals, process notes and control documentation.

1. Risk Management & Control Assessment

- Conduct periodic Risk and Control Assessments for applications, infrastructure platforms and operational processes.
- Identify technology, security and operational risks and assess the effectiveness of existing controls.
- Maintain and monitor risk registers, remediation plans and exception tracking.
- Review risk acceptance requests and compensating controls.
- Track identified risks and control gaps through closure.
- Provide risk oversight for new technology deployments, infrastructure changes and strategic initiatives.

1. User Access Governance & UAR





- Establish governance processes for User Access Management (UAM) across infrastructure and cybersecurity platforms.
- Define and maintain Access Control Matrices (ACMs) and role-based access models.
- Govern periodic User Access Reviews (UARs) for all infrastructure applications and platforms.
- Ensure access certifications are completed within defined timelines and retained for audit purposes.
- Monitor privileged access, shared IDs, service accounts and segregation of duties controls.
- Track and report access-related exceptions and remediation actions.
- Publish UAR dashboards and governance reports for senior management review.

1. Governance Oversight of Technology Functions

- Govern key initiatives and projects across Infrastructure, Cybersecurity and Cloud Operations.
- Monitor compliance with approved governance requirements during the project lifecycle.
- Assess risks associated with major technology initiatives and recommend mitigation measures.
- Engage with Technology Leadership Teams (TLTs) to address emerging governance and risk concerns.
- Support decision-making through risk-based assessments and recommendations.

1. Senior Management Reporting

- Prepare periodic dashboards and management reports covering:
- Risk Assessments
- Risk Register Status
- UAR Compliance
- Access Exceptions
- Governance Metrics
- Policy Compliance
- Control Effectiveness Reviews
- Present governance and risk updates to senior management committees.
- Perform trend analysis and highlight emerging risks and areas requiring management attention.





Educational Qualifications
- Bachelor's degree in Engineering, Information Technology, Computer Science or a related discipline.
- Master's degree or MBA preferred.
- Professional certifications preferred:
- CISA
- CRISC
- CISSP
- CISM
- ISO 27001 Lead Auditor / Lead Implementer
- COBIT Foundation / Design & Implementation

Experience
- 10-15 years of experience in Information Security, IT Risk Management, Governance or Technology Compliance.
- Minimum five years of experience in Governance, Risk Management, Internal Controls or User Access Governance.
- Experience in banking, financial services or another highly regulated industry is preferred.
- Solid understanding of technology infrastructure, cybersecurity controls and access governance practices.

Key Skills & Competencies

CategoryCompetenciesGovernance &

• RiskIT Governance Frameworks

- Risk &
- Control Assessment
- Enterprise Risk Management
- Technology Risk Assessment
- Policy &
- Standards Management
- Control Design &
- Effectiveness ReviewUser Access GovernanceUser Access Management (UAM)
- User Access Review (UAR)
- Role-Based Access Control (RBAC)
- Segregation of Duties (SoD)
- Privileged Access Governance
- Identity &
- Access Management (IAM)Leadership &
- ManagementStakeholder Management
- Executive Communication
- Presentation Skills
- Analytical Thinking
- Problem Solving
- Team Leadership
- Cross-functional CoordinationKey Performance Indicators (KPIs)

- Completion of UARs within prescribed timelines.
- Percentage reduction in access governance exceptions.
- Timely closure of identified risk and control gaps.
- Completion of periodic risk assessments.
- Accuracy and timeliness of governance dashboards.
- Compliance with governance and control review schedules.
- Reduction in overdue remediation actions.
- Improvement in overall governance and risk maturity.

📌 Information Security Engineer (Mumbai)
🏢 Kotak Mahindra Bank
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (mumbai) / mumbai